Here is the OTViewIt.txt log
OTViewIt logfile created on: 8/25/2008 9:43:47 PM - Run 1
OTViewIt by OldTimer - Version 1.0.0.12 Folder = C:\Documents and Settings\JIM\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.00 Mb Total Physical Memory | 119.48 Mb Available Physical Memory | 46.85% Memory free
735.38 Mb Paging File | 262.69 Mb Available in Paging File | 35.72% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.84 Gb Total Space | 31.81 Gb Free Space | 56.95% Space Free | Partition Type: NTFS
Drive D: | 62.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 583.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 94580ZR
Current User Name: JIM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
===== Processes - Non-Microsoft Only =====
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
[08/23/2007 08:35 AM | 00,243,064 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
[05/07/2008 10:26 PM | 00,137,200 | ---- | M] (Google) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[05/24/2004 01:35 PM | 00,322,104 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
[10/06/2003 03:16 PM | 00,081,920 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\SYSTEM32\nvsvc32.exe
[08/14/2002 08:22 PM | 00,028,672 | R--- | M] (Dell - Advanced Desktop Engineering) - C:\WINDOWS\SYSTEM32\DSentry.exe
[08/17/2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[07/03/2001 10:11 AM | 00,057,344 | ---- | M] (Hewlett-Packard) - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[11/29/2004 08:53 PM | 00,098,304 | ---- | M] (Apple Computer, Inc.) - C:\Program Files\QuickTime\qttask.exe
[07/23/2003 01:42 PM | 00,069,632 | ---- | M] (Hewlett-Packard Company) - C:\Program Files\HP DVD\Umbrella\DVDTray.exe
[06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[04/29/2008 11:41 PM | 00,185,896 | ---- | M] (RealNetworks, Inc.) - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[12/28/2005 07:21 AM | 00,270,336 | ---- | M] () - C:\Program Files\iConcepts Music Express\MEAutoDetect.exe
[05/07/2008 10:26 PM | 00,124,400 | ---- | M] (Google) - C:\Program Files\Google\Google Updater\GoogleUpdater.exe
[04/24/2002 02:28 AM | 00,487,484 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
[08/11/2004 03:22 AM | 00,757,760 | ---- | M] (Eastman Kodak Company) - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
[02/11/2004 10:00 AM | 00,118,784 | ---- | M] (WinZip Computing, Inc.) - C:\Program Files\WinZip\WZQKPICK.EXE
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
[07/03/2001 10:17 AM | 00,065,536 | ---- | M] () - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
[04/24/2002 02:50 AM | 00,299,008 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hpoevm07.exe
[04/24/2002 03:04 AM | 00,290,816 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\Hewlett-Packard\AiO\Shared\Bin\hposts07.exe
[09/17/2002 02:25 AM | 04,669,511 | ---- | M] (Adobe Systems Incorporated) - C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
[04/24/2002 02:24 AM | 00,069,632 | ---- | M] (HP) - C:\WINDOWS\SYSTEM32\hpoipm07.exe
[08/25/2008 09:42 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\JIM\Desktop\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Auto | Running]
[08/23/2007 08:35 AM | 00,243,064 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
(ccEvtMgr) Symantec Event Manager [Auto | Running]
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
(ccSetMgr) Symantec Settings Manager [Auto | Running]
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
(CLTNetCnService) Symantec Lic NetConnect service [Auto | Running]
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 03:56 AM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\SYSTEM32\dmadmin.exe
(gusvc) Google Updater Service [Auto | Running]
[05/07/2008 10:26 PM | 00,137,200 | ---- | M] (Google) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
(KodakCCS) Kodak Camera Connection Software [Auto | Running]
[05/24/2004 01:35 PM | 00,322,104 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe
(LiveUpdate) LiveUpdate [On_Demand | Stopped]
[08/23/2007 08:35 AM | 03,192,184 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
(LiveUpdate Notice) LiveUpdate Notice [Auto | Running]
[01/31/2008 02:15 PM | 00,149,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
(NMSSvc) Intel® NMS [On_Demand | Stopped]
[05/03/2002 01:29 PM | 01,118,208 | ---- | M] (Intel Corporation) - C:\WINDOWS\SYSTEM32\NMSSvc.Exe
(NVSvc) NVIDIA Display Driver Service [Auto | Running]
[10/06/2003 03:16 PM | 00,081,920 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\SYSTEM32\nvsvc32.exe
(Symantec Core LC) Symantec Core LC [On_Demand | Stopped]
[02/12/2008 11:38 AM | 01,251,720 | ---- | M] () - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
===== Driver Services - Non-Microsoft Only =====
(aeaudio) aeaudio [On_Demand | Running]
[04/01/2002 03:15 PM | 00,004,816 | ---- | M] (Andrea Electronics Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\aeaudio.sys
(AliIde) AliIde [Disabled | Stopped]
[08/17/2001 03:51 PM | 00,005,248 | ---- | M] (Acer Laboratories Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS
(amdagp) AMD AGP Bus Filter Driver [Disabled | Stopped]
[08/04/2004 02:07 AM | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys
(asc) asc [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,026,496 | ---- | M] (Advanced System Products, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS
(asc3550) asc3550 [Disabled | Stopped]
[08/17/2001 03:51 PM | 00,014,848 | ---- | M] (Advanced System Products, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS
(CmdIde) CmdIde [Disabled | Stopped]
[08/17/2001 03:51 PM | 00,006,656 | ---- | M] (CMD Technology, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS
(COH_Mon) COH_Mon [On_Demand | Stopped]
[07/30/2008 05:42 PM | 00,023,888 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
(dac2w2k) dac2w2k [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,179,584 | ---- | M] (Mylex Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS
(DcCam) Kodak Camera Proxy [System | Running]
[05/20/2004 09:21 AM | 00,036,918 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\DcCam.sys
(DcFpoint) DcFpoint [On_Demand | Stopped]
[05/20/2004 09:41 AM | 00,061,564 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\DcFpoint.sys
(DCFS2K) Kodak DCFS2K Driver [Auto | Running]
[06/02/2004 02:19 PM | 00,038,705 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\DCFS2k.sys
(DcLps) Legacy Polling Service [On_Demand | Stopped]
[05/20/2004 09:39 AM | 00,008,022 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\DcLps.sys
(DcPTP) DcPTP [On_Demand | Stopped]
[05/20/2004 09:45 AM | 00,068,950 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\DcPtp.sys
(dmboot) dmboot [Disabled | Stopped]
[08/04/2004 02:07 AM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\SYSTEM32\DRIVERS\dmboot.sys
(dmio) dmio [Disabled | Stopped]
[08/04/2004 02:07 AM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\SYSTEM32\DRIVERS\dmio.sys
(dmload) dmload [Disabled | Stopped]
[08/29/2002 07:00 AM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS
(E100B) Intel® PRO Adapter Driver [On_Demand | Running]
[04/30/2002 02:53 PM | 00,139,776 | ---- | M] (Intel Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys
(eeCtrl) Symantec Eraser Control driver [System | Running]
[01/22/2008 05:00 AM | 00,385,072 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
(EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [On_Demand | Stopped]
[08/17/2001 02:11 PM | 00,066,591 | ---- | M] (3Com Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS
(EraserUtilRebootDrv) EraserUtilRebootDrv [On_Demand | Running]
[01/22/2008 05:00 AM | 00,109,616 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
(Exportit) Exportit [System | Stopped]
[06/02/2004 02:17 PM | 00,151,985 | ---- | M] (Eastman Kodak Company) - C:\WINDOWS\SYSTEM32\DRIVERS\ExportIt.sys
(i81x) i81x [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,161,020 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys
(iAimFP0) iAimFP0 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,012,415 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys
(iAimFP1) iAimFP1 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,012,127 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys
(iAimFP2) iAimFP2 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,011,775 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys
(iAimFP3) iAimFP3 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,012,063 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys
(iAimFP4) iAimFP4 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,019,455 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys
(iAimTV0) iAimTV0 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,029,311 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys
(iAimTV1) iAimTV1 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,019,551 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys
(iAimTV3) iAimTV3 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,033,599 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys
(iAimTV4) iAimTV4 [On_Demand | Stopped]
[08/04/2004 01:29 AM | 00,023,615 | ---- | M] (Intel® Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys
(MASPINT) MASPINT [Auto | Running]
[06/21/2002 07:42 PM | 00,008,224 | ---- | M] (MicroStaff Co.,Ltd.) - C:\WINDOWS\System32\drivers\MASPINT.SYS
(mraid35x) mraid35x [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,017,280 | ---- | M] (American Megatrends Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS
(NAVENG) NAVENG [On_Demand | Running]
[07/12/2008 01:00 AM | 00,089,936 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080712.002\NAVENG.SYS
(NAVEX15) NAVEX15 [On_Demand | Running]
[07/12/2008 01:00 AM | 00,856,336 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080712.002\NAVEX15.SYS
(NMSCFG) NIC Management Service Configuration Driver [On_Demand | Stopped]
[05/03/2002 01:30 PM | 00,009,868 | ---- | M] (Intel Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\NMSCFG.SYS
(nv) nv [On_Demand | Running]
[10/06/2003 03:16 PM | 01,550,043 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys
(omci) OMCI WDM Device Driver [System | Running]
[07/19/2002 12:22 PM | 00,017,153 | ---- | M] (Dell Computer Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys
(pfc) Padus ASPI Shell [On_Demand | Running]
[09/19/2003 04:47 PM | 00,010,368 | ---- | M] (Padus, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[08/29/2002 07:00 AM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS
(PxHelp20) PxHelp20 [Boot | Running]
[04/22/2004 03:02 AM | 00,020,368 | ---- | M] (Sonic Solutions) - C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys
(PZYRXTAK) PZYRXTAK [Auto | Stopped]
File not found - C:\WINDOWS\system32\pzyrxtak.wes
(ql1080) ql1080 [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,040,320 | ---- | M] (QLogic Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS
(ql12160) ql12160 [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,045,312 | ---- | M] (QLogic Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS
(ql1280) ql1280 [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,049,024 | ---- | M] (QLogic Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS
(Secdrv) Secdrv [On_Demand | Stopped]
[11/13/2007 06:25 AM | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys
(sisagp) SIS AGP Bus Filter [Disabled | Stopped]
[08/04/2004 02:07 AM | 00,041,088 | ---- | M] (Silicon Integrated Systems Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys
(smwdm) smwdm [On_Demand | Running]
[08/05/2002 11:23 AM | 00,545,208 | ---- | M] (Analog Devices, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys
(Sparrow) Sparrow [Disabled | Stopped]
[08/17/2001 04:07 PM | 00,019,072 | ---- | M] (Adaptec, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS
(SPBBCDrv) SPBBCDrv [System | Running]
[08/17/2007 09:23 AM | 00,446,512 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
(SQTECH905C) DualCamera [On_Demand | Stopped]
[07/13/2005 11:08 AM | 00,033,890 | ---- | M] (Service & Quality Technology.) - C:\WINDOWS\SYSTEM32\DRIVERS\Capt905c.sys
(SRS_SSCFilter) SRS Labs Audio Sandbox (WDM) [On_Demand | Stopped]
[05/03/2007 10:28 AM | 00,039,552 | R--- | M] () - C:\WINDOWS\SYSTEM32\DRIVERS\SRS_SSCFilter_i386.sys
(SRTSP) SRTSP [On_Demand | Running]
[12/01/2007 12:57 AM | 00,279,088 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\srtsp.sys
(SRTSPL) SRTSPL [On_Demand | Stopped]
[12/01/2007 12:57 AM | 00,317,616 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\srtspl.sys
(SRTSPX) SRTSPX [System | Running]
[12/01/2007 12:57 AM | 00,043,696 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\srtspx.sys
(symc810) symc810 [Disabled | Stopped]
[08/17/2001 04:07 PM | 00,016,256 | ---- | M] (Symbios Logic Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS
(symc8xx) symc8xx [Disabled | Stopped]
[08/17/2001 04:07 PM | 00,032,640 | ---- | M] (LSI Logic) - C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS
(SYMDNS) SYMDNS [On_Demand | Running]
[08/13/2007 08:50 AM | 00,013,616 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symdns.sys
(SymEvent) SymEvent [On_Demand | Running]
[06/03/2008 06:04 PM | 00,123,952 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
(SYMFW) SYMFW [On_Demand | Running]
[08/13/2007 08:50 AM | 00,096,432 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symfw.sys
(SYMIDS) SYMIDS [On_Demand | Running]
[08/13/2007 08:50 AM | 00,038,576 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symids.sys
(SYMIDSCO) SYMIDSCO [On_Demand | Running]
[02/13/2008 12:18 PM | 00,240,496 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20080617.001\SymIDSCo.sys
(SymIM) Symantec Network Security Intermediate Filter Service [On_Demand | Stopped]
[08/09/2007 12:27 PM | 00,031,280 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\SymIM.sys
(SymIMMP) SymIMMP [On_Demand | Running]
[08/09/2007 12:27 PM | 00,031,280 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\SymIM.sys
(SYMNDIS) SYMNDIS [On_Demand | Running]
[08/13/2007 08:50 AM | 00,037,424 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symndis.sys
(SYMREDRV) SYMREDRV [On_Demand | Running]
[08/13/2007 08:50 AM | 00,022,320 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symredrv.sys
(SYMTDI) SYMTDI [System | Running]
[08/13/2007 08:50 AM | 00,188,464 | ---- | M] (Symantec Corporation) - C:\WINDOWS\SYSTEM32\DRIVERS\symtdi.sys
(sym_hi) sym_hi [Disabled | Stopped]
[08/17/2001 04:07 PM | 00,028,384 | ---- | M] (LSI Logic) - C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS
(sym_u3) sym_u3 [Disabled | Stopped]
[08/17/2001 04:07 PM | 00,030,688 | ---- | M] (LSI Logic) - C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS
(ultra) ultra [Disabled | Stopped]
[08/17/2001 03:52 PM | 00,036,736 | ---- | M] (Promise Technology, Inc.) - C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS
(X4HS32) X4HS32 [Auto | Running]
[12/02/2003 01:26 PM | 00,021,627 | ---- | M] (Exent Technologies Ltd.) - C:\Program Files\EXEtender\X4HS32.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BearFlix" = "C:\Program Files\BearFlix\BearFlix.exe" /pause File not found
"BIO" = C:\WINDOWS\BIO.exe File not found
"ccApp" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/31/2008 02:15 PM | 00,051,048 | ---- | M] (Symantec Corporation)
"DVDBitSet" = "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI [12/18/2003 05:37 PM | 00,184,320 | ---- | M] (Hewlett-Packard Company)
"DVDSentry" = C:\WINDOWS\System32\DSentry.exe [08/14/2002 08:22 PM | 00,028,672 | R--- | M] (Dell - Advanced Desktop Engineering)
"DVDTray" = "C:\Program Files\HP DVD\Umbrella\DVDTray.exe" [07/23/2003 01:42 PM | 00,069,632 | ---- | M] (Hewlett-Packard Company)
"Microsoft Works Update Detection" = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [08/17/2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation)
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [10/06/2003 03:16 PM | 05,058,560 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [10/06/2003 03:16 PM | 00,049,152 | ---- | M] (NVIDIA Corporation)
"nwiz" = nwiz.exe /install [10/06/2003 03:16 PM | 00,741,376 | ---- | M] (NVIDIA Corporation)
"osCheck" = "C:\Program Files\Norton AntiVirus\osCheck.exe" [08/24/2007 04:53 PM | 00,714,608 | ---- | M] (Symantec Corporation)
"QuickTime Task" = "C:\Program Files\QuickTime\qttask.exe" -atboottime [11/29/2004 08:53 PM | 00,098,304 | ---- | M] (Apple Computer, Inc.)
"REGSHAVE" = C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN [02/04/2002 11:32 PM | 00,053,248 | ---- | M] (FUJI PHOTO FILM CO., LTD.)
"Share-to-Web Namespace Daemon" = C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [07/03/2001 10:11 AM | 00,057,344 | ---- | M] (Hewlett-Packard)
"shawnotify" = c:\progra~1\shaw\update\siuloader.exe /notify [07/15/2008 03:37 PM | 00,378,144 | ---- | M] (Shaw Cablesystems)
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
"TkBellExe" = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot [04/29/2008 11:41 PM | 00,185,896 | ---- | M] (RealNetworks, Inc.)
"UpdateManager" = "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r [08/19/2003 02:01 AM | 00,110,592 | ---- | M] (Sonic Solutions)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
"" = File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox" = "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox" = "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme File not found
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[12/28/2005 07:21 AM | 00,270,336 | ---- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Auto Detect.lnk = C:\Program Files\iConcepts Music Express\MEAutoDetect.exe
[05/07/2008 10:26 PM | 00,124,400 | ---- | M] (Google) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
[04/24/2002 02:28 AM | 00,487,484 | ---- | M] (Hewlett-Packard Co.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
[08/11/2004 03:22 AM | 00,757,760 | ---- | M] (Eastman Kodak Company) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
[02/11/2004 10:00 AM | 00,118,784 | ---- | M] (WinZip Computing, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
[JIM Startup Folder - C:\Documents and Settings\JIM\Start Menu\Programs\Startup]
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (AcroIEHlprObj Class) - [04/16/2001 05:39 PM | 00,037,808 | ---- | M] () C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
HKLM CLSID: (RealPlayer Download and Record Plugin for Internet Explorer) - [04/29/2008 11:42 PM | 00,308,856 | ---- | M] (RealPlayer) C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
HKLM CLSID: (Symantec Intrusion Prevention) - [02/12/2008 11:40 AM | 00,116,088 | ---- | M] (Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
HKLM CLSID: (Google Toolbar Notifier BHO) - [05/07/2008 10:26 PM | 00,654,320 | ---- | M] (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3215F20-3212-11D6-9F8B-00D0B743919D}]
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
Unable to open key or key not present!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage" = 0
"NoDispScrSavPage" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-21-4169335272-1270071699-3278186619-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"NoDispBackgroundPage" = 0
"NoDispScrSavPage" = 0
===== Desktop Components =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = ""
"Source" = "
http://ca.f412.mail....&view=a&head=b"
"SubscribedURL" = "
http://ca.f412.mail....&view=a&head=b"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2]
"FriendlyName" = "Intelligent Desktop - intelligentdesktop.com"
"Source" = "
http://active.intell...tive/?18069318"
"SubscribedURL" = "
http://active.intell...com/active.cdf"
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
===== Lsa Authentication Packages =====
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\SYSTEM32\sessmgr.exe [08/04/2004 03:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\sessmgr.exe" = C:\WINDOWS\SYSTEM32\sessmgr.exe [08/04/2004 03:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe [06/23/2008 05:20 AM | 00,625,664 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Real\RealOne Player\realplay.exe" = C:\Program Files\Real\RealOne Player\realplay.exe File not found
"C:\Program Files\Grisoft\AVG Free\avgw.exe" = C:\Program Files\Grisoft\AVG Free\avgw.exe File not found
"C:\Program Files\Grisoft\AVG Free\avgcc.exe" = C:\Program Files\Grisoft\AVG Free\avgcc.exe File not found
"C:\Program Files\Grisoft\AVG Free\avgvv.exe" = C:\Program Files\Grisoft\AVG Free\avgvv.exe File not found
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [02/11/2004 05:58 PM | 00,016,423 | ---- | M] ()
"C:\Program Files\Yahoo! Games\Cubis Gold 2\cubis2.exe" = C:\Program Files\Yahoo! Games\Cubis Gold 2\cubis2.exe File not found
"C:\WINDOWS\SYSTEM32\dpvsetup.exe" = C:\WINDOWS\SYSTEM32\dpvsetup.exe [08/04/2004 03:56 AM | 00,083,456 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\SYSTEM32\rundll32.exe" = C:\WINDOWS\SYSTEM32\rundll32.exe [08/04/2004 03:56 AM | 00,033,280 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Shaw Secure\backweb\3875767\Program\fspex.exe" = C:\Program Files\Shaw Secure\backweb\3875767\Program\fspex.exe File not found
"C:\Program Files\Yahoo! Games\Blasterball 2 Remix\bb2remix.exe" = C:\Program Files\Yahoo! Games\Blasterball 2 Remix\bb2remix.exe File not found
"C:\Program Files\GameHouse\GemDrop\GemDrop.exe" = C:\Program Files\GameHouse\GemDrop\GemDrop.exe File not found
"C:\Program Files\BearShare\BearShare.exe" = C:\Program Files\BearShare\BearShare.exe File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\BearFlix\bearflix.exe" = C:\Program Files\BearFlix\bearflix.exe File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe File not found
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06/13/2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 03:56 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\SYSTEM32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 03:56 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\SYSTEM32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\SYSTEM32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 03:56 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\SYSTEM32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = msnmsgr
"hkey" = HKCU
"command" = C:\Program Files\MSN Messenger\msnmsgr.exe File not found
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
"system.ini" = 0
"win.ini" = 0
"bootini" = 0
"services" = 0
"startup" = 2
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{A5FC9EB4-564C-4C28-B571-ED16385258D5}]
Servers: | Description: Intel® PRO/100 VE Network Connection
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{E1918B6A-BF8B-4428-9A90-3F41192FF1F0}]
Servers: | Description:
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== Autorun Files on Drives =====
AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ]
[12/25/2004 12:43 PM | 00,000,050 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
AUTORUN.EXE [MZP | ]
[12/22/1997 10:54 AM | 00,055,808 | R--- | M] () D:\AUTORUN.EXE [ CDFS ]
AUTORUN.INF [[autorun] | open=launcher.exe | icon=encore.ico | ]
[09/14/2000 12:59 PM | 00,000,045 | R--- | M] () D:\AUTORUN.INF [ CDFS ]
Autorun.exe [MZ | ]
[10/02/2001 06:13 AM | 00,299,008 | R--- | M] () E:\Autorun.exe [ CDFS ]
autorun.inf [[autorun] | open=autorun.exe | icon=CD.ico | ]
[09/12/2001 12:18 PM | 00,000,040 | R--- | M] () E:\autorun.inf [ CDFS ]
autorun.pcx [ | | ]
[08/30/2001 01:55 PM | 00,189,819 | R--- | M] () E:\autorun.pcx [ CDFS ]
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{725447b7-8fe6-11db-91c2-0007e9c8fee6}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{725447b7-8fe6-11db-91c2-0007e9c8fee6}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\SYSTEM32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{725447b7-8fe6-11db-91c2-0007e9c8fee6}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{81207a42-6e40-11d8-b5bd-0007e9c8fee6}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{81207a42-6e40-11d8-b5bd-0007e9c8fee6}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\SYSTEM32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{81207a42-6e40-11d8-b5bd-0007e9c8fee6}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe99e83e-7848-11dc-91f1-0007e9c8fee6}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe99e83e-7848-11dc-91f1-0007e9c8fee6}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\SYSTEM32\shell32.dll [10/25/2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe99e83e-7848-11dc-91f1-0007e9c8fee6}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun]
"" = Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\Shell\AutoRun\command]
"" = D:\launcher.exe [01/14/2001 03:34 PM | 00,188,464 | R--- | M] ()
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun]
"" = Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]
"" = E:\autorun.exe [10/02/2001 06:13 AM | 00,299,008 | R--- | M] ()
===== Hosts File =====
HOSTS File = (23 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 90 days]
[06/14/2008 10:21 PM | ---D | C] - C:\unzipped
[07/09/2008 08:24 AM | ---D | C] - C:\DISNEY
[08/01/2008 12:19 AM | ---D | C] - C:\temp
[08/22/2008 09:04 AM | ---D | C] - C:\VundoFix Backups
[08/25/2008 05:35 PM | 26,746,0608 | -HS- | C] () - C:\hiberfil.sys
[08/17/2008 03:01 PM | 00,017,144 | ---- | C] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbam.sys
[08/17/2008 03:01 PM | 00,038,472 | ---- | C] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[06/10/2008 02:32 AM | 00,139,264 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[11/18/2003 12:37 AM | 00,072,192 | ---- | C] () - C:\WINDOWS\System32\zlib.dll
[11/22/2007 10:00 AM | 00,483,328 | ---- | C] (SoftShape Development) - C:\WINDOWS\System32\actskn45.ocx
[4 C:\WINDOWS\*.tmp files]
[07/04/2008 07:21 AM | ---D | C] - C:\WINDOWS\.jagex_cache_32
[07/09/2008 08:43 AM | 00,000,333 | ---- | C] () - C:\WINDOWS\7THLEVEL.INI
[08/25/2008 03:39 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[1 C:\Documents and Settings\JIM\Application Data\*.tmp files]
[07/21/2008 12:21 PM | ---D | C] - C:\Documents and Settings\JIM\Application Data\BearShare
[08/25/2008 03:40 PM | ---D | C] - C:\Documents and Settings\JIM\Application Data\Malwarebytes
[06/29/2008 10:48 PM | ---D | C] - C:\Documents and Settings\JIM\Local Settings\Application Data\Oberon Games
[07/31/2008 11:50 AM | 00,000,681 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Shaw Support.lnk
[06/18/2008 10:51 AM | ---D | C] - C:\Documents and Settings\JIM\Desktop\Soccer
[08/24/2008 07:02 PM | 00,000,226 | ---- | C] () - C:\Documents and Settings\JIM\Desktop\Welcome to Webkinz® - a Ganz website.url
@Alternate Data Stream - 2550 bytes -> %UserProfile%\Desktop\Welcome to Webkinz® - a Ganz website.url:favicon
[08/25/2008 09:42 PM | 01,299,968 | ---- | C] (OldTimer Tools) - C:\Documents and Settings\JIM\Desktop\OTViewIt.exe
[07/21/2008 10:24 AM | ---D | C] - C:\Program Files\BearShare Applications
[07/31/2008 11:51 AM | ---D | C] - C:\Program Files\shaw
[08/22/2008 08:27 AM | ---D | C] - C:\Program Files\Trend Micro
[08/25/2008 03:40 PM | ---D | C] - C:\Program Files\Malwarebytes' Anti-Malware
[Files/Folders - Modified Within 90 days]
[06/14/2008 10:21 PM | ---D | M] - C:\unzipped
[07/09/2008 08:24 AM | ---D | M] - C:\DISNEY
[07/27/2008 02:58 AM | ---D | M] - C:\My Games
[08/01/2008 12:19 AM | ---D | M] - C:\temp
[08/12/2008 06:02 PM | ---D | M] - C:\My Download Files
[08/19/2008 09:38 AM | -HSD | M] - C:\System Volume Information
[08/22/2008 09:04 AM | ---D | M] - C:\VundoFix Backups
[08/25/2008 05:32 PM | ---D | M] - C:\Program Files
[08/25/2008 05:34 PM | ---D | M] - C:\WINDOWS
[08/25/2008 05:35 PM | 26,746,0608 | -HS- | M] () - C:\hiberfil.sys
[06/03/2008 06:04 PM | 00,000,805 | ---- | M] () - C:\WINDOWS\System32\drivers\SYMEVENT.INF
[06/03/2008 06:04 PM | 00,010,671 | ---- | M] () - C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[06/03/2008 06:04 PM | 00,123,952 | ---- | M] (Symantec Corporation) - C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[07/30/2008 05:28 PM | 00,000,706 | ---- | M] () - C:\WINDOWS\System32\drivers\COH_Mon.inf
[07/30/2008 05:28 PM | 00,010,537 | ---- | M] () - C:\WINDOWS\System32\drivers\coh_mon.cat
[07/30/2008 05:42 PM | 00,023,888 | ---- | M] (Symantec Corporation) - C:\WINDOWS\System32\drivers\COH_Mon.sys
[08/17/2008 03:01 PM | 00,017,144 | ---- | M] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbam.sys
[08/17/2008 03:01 PM | 00,038,472 | ---- | M] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2 C:\WINDOWS\System32\*.tmp files]
[06/03/2008 06:04 PM | 00,060,800 | ---- | M] (Symantec Corporation) - C:\WINDOWS\System32\S32EVNT1.DLL
[06/10/2008 01:21 AM | 00,135,168 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[06/10/2008 01:21 AM | 00,135,168 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[06/10/2008 02:32 AM | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javacpl.cpl
[06/10/2008 02:32 AM | 00,139,264 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[06/21/2008 12:37 PM | ---D | M] - C:\WINDOWS\System32\Adobe
[08/19/2008 09:36 AM | RHSD | M] - C:\WINDOWS\System32\DLLCACHE
[08/19/2008 09:38 AM | ---D | M] - C:\WINDOWS\System32\Restore
[08/25/2008 05:34 PM | ---D | M] - C:\WINDOWS\System32\DRIVERS
[08/25/2008 05:35 PM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[08/25/2008 05:37 PM | 00,001,170 | ---- | M] () - C:\WINDOWS\System32\WPA.DBL
[4 C:\WINDOWS\*.tmp files]
[07/04/2008 07:21 AM | ---D | M] - C:\WINDOWS\.jagex_cache_32
[07/07/2008 01:40 PM | ---D | M] - C:\WINDOWS\Registration
[07/09/2008 08:43 AM | 00,000,333 | ---- | M] () - C:\WINDOWS\7THLEVEL.INI
[07/20/2008 10:22 AM | --SD | M] - C:\WINDOWS\Downloaded Program Files
[08/01/2008 12:50 PM | 00,000,207 | ---- | M] () - C:\WINDOWS\encore_launcher.ini
[08/15/2008 06:05 AM | ---D | M] - C:\WINDOWS\ie7updates
[08/15/2008 06:10 AM | -HSD | M] - C:\WINDOWS\Installer
[08/15/2008 06:11 AM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/15/2008 06:11 AM | -H-D | M] - C:\WINDOWS\$hf_mig$
[08/18/2008 05:27 PM | ---D | M] - C:\WINDOWS\Help
[08/20/2008 12:39 AM | -H-D | M] - C:\WINDOWS\INF
[08/25/2008 05:35 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\BOOTSTAT.DAT
[08/25/2008 05:37 PM | 00,054,156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[08/25/2008 08:19 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/25/2008 09:41 PM | ---D | M] - C:\WINDOWS\SYSTEM32
[08/25/2008 09:41 PM | ---D | M] - C:\WINDOWS\Temp
[08/25/2008 03:30 AM | 00,000,398 | ---- | M] () - C:\WINDOWS\tasks\ErrorSmart Scheduled Scan.job
[08/25/2008 05:35 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/25/2008 08:19 AM | 00,000,552 | ---- | M] () - C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - JIM.job
[08/25/2008 08:57 PM | 00,000,254 | ---- | M] () - C:\WINDOWS\tasks\Windows Update.job
[06/29/2008 08:41 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\PlayFirst
[08/05/2008 09:37 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Symantec
[08/25/2008 02:18 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Google Updater
[08/25/2008 03:39 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[1 C:\Documents and Settings\JIM\Application Data\*.tmp files]
[06/21/2008 12:25 PM | ---D | M] - C:\Documents and Settings\JIM\Application Data\Adobe
[06/29/2008 08:41 PM | ---D | M] - C:\Documents and Settings\JIM\Application Data\PlayFirst
[07/21/2008 12:21 PM | ---D | M] - C:\Documents and Settings\JIM\Application Data\BearShare
[08/25/2008 03:40 PM | ---D | M] - C:\Documents and Settings\JIM\Application Data\Malwarebytes
[06/29/2008 10:48 PM | ---D | M] - C:\Documents and Settings\JIM\Local Settings\Application Data\Oberon Games
[08/05/2008 09:36 PM | ---D | M] - C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft
[08/25/2008 05:33 PM | 01,582,038 | -H-- | M] () - C:\Documents and Settings\JIM\Local Settings\Application Data\IconCache.db
[08/06/2008 11:03 PM | 01,598,464 | R--- | M] () - C:\Documents and Settings\All Users\Documents\ESBK.mb
[08/06/2008 11:03 PM | 03,074,048 | R--- | M] () - C:\Documents and Settings\All Users\Documents\ESBK.mbb
[06/02/2008 02:34 PM | ---D | M] - C:\Documents and Settings\JIM\My Documents\My Games
[06/10/2008 04:29 PM | 00,037,888 | ---- | M] () - C:\Documents and Settings\JIM\My Documents\Books Read.xlr
[06/10/2008 05:27 PM | 00,028,160 | ---- | M] () - C:\Documents and Settings\JIM\My Documents\Books To Look For.xlr
[07/21/2008 11:50 AM | R--D | M] - C:\Documents and Settings\JIM\My Documents\My Music
[08/24/2008 02:13 AM | R--D | M] - C:\Documents and Settings\JIM\My Documents\My Pictures
[07/31/2008 11:50 AM | 00,000,681 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Shaw Support.lnk
[06/18/2008 10:51 AM | ---D | M] - C:\Documents and Settings\JIM\Desktop\Soccer
[07/21/2008 02:20 PM | R--D | M] - C:\Documents and Settings\JIM\Desktop\Bearshare
[08/07/2008 03:08 PM | R--D | M] - C:\Documents and Settings\JIM\Desktop\Unused Files
[08/21/2008 01:24 AM | ---D | M] - C:\Documents and Settings\JIM\Desktop\JOB POSTINGS
[08/24/2008 07:02 PM | 00,000,226 | ---- | M] () - C:\Documents and Settings\JIM\Desktop\Welcome to Webkinz® - a Ganz website.url
@Alternate Data Stream - 2550 bytes -> %UserProfile%\Desktop\Welcome to Webkinz® - a Ganz website.url:favicon
[08/25/2008 05:57 PM | R--D | M] - C:\Documents and Settings\JIM\Desktop\SCAN PROGRAMS
[08/25/2008 09:42 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\JIM\Desktop\OTViewIt.exe
[08/19/2008 09:58 AM | ---D | M] - C:\Program Files\Common Files\Symantec Shared
< End of report >
and here is the Extrs.txt log
OTViewIt Extras logfile created on: 8/25/2008 9:43:47 PM - Run 1
OTViewIt by OldTimer - Version 1.0.0.12 Folder = C:\Documents and Settings\JIM\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.00 Mb Total Physical Memory | 119.48 Mb Available Physical Memory | 46.85% Memory free
735.38 Mb Paging File | 262.69 Mb Available in Paging File | 35.72% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.84 Gb Total Space | 31.81 Gb Free Space | 56.95% Space Free | Partition Type: NTFS
Drive D: | 62.24 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 583.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
===== File Associations =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] - File not found -
.cmd [@ = cmdfile] - File not found -
.com [@ = comfile] - File not found -
.exe [@ = exefile] - File not found -
.pif [@ = piffile] - File not found -
.scr [@ = scrfile] - File not found -
===== Uninstall List =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{01001202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard 2002
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}" = Civilization III
"{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}" = Security Update for CAPICOM (KB931906)
"{1063EB55-E42D-4755-9F83-BF20389E5524}" = TAXWIZ 2006
"{10E98E14-832C-4AF7-A4D1-6A9EF83B282E}" = VCAMCEN
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{12BDDF23-B1DB-49C8-92D3-3E6841CCED61}" = Microsoft Streets and Trips 2002
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1666FA7C-CB5F-11D6-A78C-00B0D079AF64}" = Java 2 Runtime Environment, SE v1.4.1_01
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}" = QuickTax 2007
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.0
"{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = EXEtender Player
"{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}